
Bank Impersonation Scams: Hang Up and Call Back
A bank impersonation scam rarely opens with a stranger fishing for your details. It opens with someone who already has them: your name, the last four digits of your card, the town you live in, sometimes a purchase you made yesterday.
Most people assume that detail could only come from inside the institution, and that assumption gets the call past their guard.
Payment fraud across the European Economic Area reached €4.2 billion in 2024, up from €3.5 billion the year before, according to the joint EBA-ECB report on payment fraud.
For credit transfers, payment service users bore roughly 85% of the losses, mainly because they were manipulated into starting the payment themselves.
How a bank impersonation scam works
The call follows a script. Credibility comes first: the caller opens with information only your provider should hold and asks nothing of you. The alarm, usually triggered by a payment attempt from a terminal abroad, is delivered in a tone of concern on your behalf.
The instruction comes last. Because the account is "compromised", the money has to move to a safe account while the fraud team investigates. Or read out the code that just arrived by SMS. Or install a support app so an engineer can secure your device.
A specific version: someone in Valencia picks up at 6:40pm, the screen showing their provider's published support number. The caller confirms the last four digits of the card and a €38.90 supermarket payment from Tuesday, then reports a blocked €1,240 attempt abroad and says the balance has to be moved tonight into a holding account the fraud team has opened. He reads out the IBAN and talks the customer through the transfer in their own app.
At 6:52pm, the customer taps confirm. The account belongs to a money mule, and the money is withdrawn within the hour.
Vishing, short for voice phishing, is the delivery method. A vishing scam defeats no security system, because the person holding the credentials is persuaded to use them. Bank impersonation fraud is the wider label, and a fake bank phone call is its cheapest form.
How a scammer knows personal information about you
The answer is almost never an insider. It is the residue of every service you have signed up for.
Data protection authorities in Europe were notified of an average of 443 personal data breaches per day during the year from 28 January 2025, a 22% rise and the first time the daily average has exceeded 400 since the GDPR took effect. Each one represents a set of records: names, numbers, addresses, partial payment details, and often the provider you use.
Europol’s Internet Organised Crime Threat Assessment describes stolen data being resold and re-exploited by other criminal groups, so the same people are targeted repeatedly. That is the supply chain behind data breach scam calls.
Europol also notes that fraudsters are using generative AI to impersonate helpdesk staff at scale, in fluent local languages.
So when a scammer knows personal information about you, read it as evidence of a leak, not of who is on the line.
Bank caller ID spoofing and why the number proves nothing
Can a bank phone number be spoofed? Easily. Caller ID began as a courtesy feature on networks where every operator was a trusted national monopoly, and the number shown is supplied by whoever starts the call. Nothing along the route checks it.
Bank caller ID spoofing follows from that design: software sets the outgoing number to a provider’s published support line, so the call appears to come from the number on your card.
Italy shows the limits of the fix. AGCOM (Italian Communications Regulatory Authority) blocked tens of millions of spoofed calls within days and pushed the same operations onto international numbers that current rules do not allow operators to block. Should I trust the caller ID from my bank? Not as identification, however familiar the number looks.
Hang up and call your bank
One rule survives every version of this scam, and it asks nothing of your ability to spot a fake. Hang up and call your bank back on a number you found yourself. A caller controls what you see and hear, but not which number you dial.
How to verify a call from my bank, step by step:
- End the call. You do not owe the caller an explanation.
- Find the number yourself: on your card, in your provider’s app, or on the official site you navigate to directly. Never the one the caller gives you.
- Use in-app chat where available; it is authenticated with your login.
- Ask whether anyone contacted you in the last hour. The answer is usually no.
Every version of this scam needs one of the following, and no legitimate provider ever requests them.
| What the caller asks for | What a regulated provider does |
|---|---|
| Moving your money to a „safe account“ | Never. It restricts or blocks the account from its own side. |
| A one-time code from SMS or the app | Never. The code proves it is you; reading it out defeats it. |
| Your full card number, PIN or password | Never. Staff already see what they need. |
| Installing remote-access or „support“ software | Never. That hands over your screen and session. |
| Keeping it secret from family or branch staff | Never. Secrecy protects the caller, not you. |
Common requests in a bank impersonation call, against normal practice at a regulated provider.
Will a real bank ask me to transfer money? No, and that is the most reliable tell: the "safe account" line turns a fraud that would need stolen credentials into a payment you authorise yourself. If you are wondering what to do during a suspicious bank call, the answer is: confirm nothing, agree to nothing, and end it.
Blackcat contacts and card security
Blackcat is a payment account and payment card issued by Papaya Ltd, licensed by the Malta Financial Services Authority as an Electronic Money Institution, registration number C55146.
- Official contacts are support@blackcat.app and the in-app chat. Support will not ask for your PIN, full card number, password or a one-time code, and will never ask you to move money.
- You can block your payment card yourself: open the app, select the card, and tap Block card. It applies immediately and is reversible.
- Every Blackcat payment card is enrolled in 3D Secure by default, and transactions are continuously monitored, with payments declined or sent for review when a pattern appears suspicious.
- Clone sites imitating Blackcat exist. The only official address is blackcat.app, so check the address bar.
Find more on account and card protection on the Blackcat security page.
FAQ:
How does a scammer know my personal information?
Almost always from a data breach, not from inside your provider. Leaked records are traded and resold, so the file already exists.
Can scammers spoof a bank’s phone number?
Yes. Caller ID is set by whoever starts the call and is not verified, so any number can be displayed.
How can I verify a call from my bank?
End the call and dial back on a number you sourced yourself: your card, the app, or the official site.
What is a vishing scam?
Vishing is voice phishing: fraud by phone call, in which the caller impersonates a trusted organisation to obtain codes or a transfer.
Should I trust the name shown by the caller ID?
No. Both are display fields that the caller sets. Treat them as a label, never an identification.
What should I do during a suspicious bank call?
Confirm nothing, agree to nothing, install nothing, end the call. If you are worried, block your card in the app.
Will a real bank ask me to move money to another account?
No. A regulated provider protects an account by restricting it from its own side, so an instruction to move funds is a scam.
Where can I report a fake bank call?
Tell your provider first, using contacts from their app or official site, then the police or a national fraud reporting service.